# Extract value from regex with parentheses in if condition

**URL:** <https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190>\
**Category:** Logstash\
**Created:** [March 24, 2021, 10:01am UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190 "2021-03-24T10:01:03Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Romanian\_Coder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romanian_coder/32/84041_2.png) [@Romanian\_Coder](https://discuss.elastic.co/u/Romanian_Coder)\
**Post date:** [March 24, 2021, 10:01am UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/1 "2021-03-24T10:01:03Z")

</div>

I have next input in logstash

```auto
 {
logstash | "sourceRecordPosition" => 11,
logstash | "rejectionReason" => "",
logstash | "key" => 2251799813685255,
logstash | "brokerVersion" => "0.26.0",
logstash | "value" => {
logstash | "workflowInstanceKey" => 2251799813685254,
logstash | "scopeKey" => 2251799813685254,
logstash | "value" => "\"fire\"",
logstash | "name" => "emergencyReason",
logstash | "workflowKey" => 2251799813685249
logstash | },
logstash | "valueType" => "VARIABLE",
logstash | "rejectionType" => "NULL_VAL",
logstash | "position" => 12,
logstash | "partitionId" => 1,
logstash | "recordType" => "EVENT",
logstash | "@version" => "1",
logstash | "@timestamp" => 2021-03-24T09:50:13.570Z,
logstash | "intent" => "CREATED"
logstash | }

```

And I wrote grok filter with regex ( [regex101: build, test, and debug regex](https://regex101.com/r/dIJjlm/1) ) for extract value by group,

```auto
 filter { 
        json { 
           source => "message"
        }

        if [value][value] =~ /^"\\"(\S+)\\""/ {
            mutate { 
                 gsub => ["[value][value]", '^"\\"(\S+)\\""', "\1" ]
           }
       }
} 

```

But this not work for me. How can I extract value?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 24, 2021, 2:55pm UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/2 "2021-03-24T14:55:52Z")

</div>

> [@Romanian\_Coder](#):
>
> But this not work for me.

What does that mean?

---

<div class="post-metadata">

**Author:** ![Romanian\_Coder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romanian_coder/32/84041_2.png) [@Romanian\_Coder](https://discuss.elastic.co/u/Romanian_Coder)\
**Post date:** [March 24, 2021, 5:43pm UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/3 "2021-03-24T17:43:49Z")

</div>

I mean I want to extract word fire from parentheses, like this `"\"fire\"" -> fire` and put this word in [value][value] field

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 24, 2021, 6:24pm UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/4 "2021-03-24T18:24:02Z")

</div>

```
"value" => "\"fire\"",

```

The actual value of the [value][value] field is `"fire"`. The additional quotes and backslashes are just presentation by rubydebug, so all you need to do is remove the double quotes.

```
mutate { gsub => ["[value][value]", '"', "" ] }
```

---

<div class="post-metadata">

**Author:** ![Romanian\_Coder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romanian_coder/32/84041_2.png) [@Romanian\_Coder](https://discuss.elastic.co/u/Romanian_Coder)\
**Post date:** [March 25, 2021, 4:42am UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/5 "2021-03-25T04:42:34Z")

</div>

Unfortunately, exactly this word with backslashes going to elastic index

---

<div class="post-metadata">

**Author:** ![Romanian\_Coder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romanian_coder/32/84041_2.png) [@Romanian\_Coder](https://discuss.elastic.co/u/Romanian_Coder)\
**Post date:** [March 25, 2021, 5:02am UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/6 "2021-03-25T05:02:22Z")

</div>

Here is a some data from index

```auto
"hits": {
        "total": 198697,
        "max_score": 1.0,
        "hits": [
            {
                "_index": "zeebe_variable_0.26.0_2021-03-18",
                "_type": "_doc",
                "_id": "1-6780",
                "_score": 1.0,
                "_routing": "1",
                "_source": {
                    "partitionId": 1,
                    "value": {
                        "name": "emergencyReason",
                        "value": "\"fire\"",
                        "workflowKey": 2251799813685249,
                        "workflowInstanceKey": 2251799813685254,
                        "scopeKey": 2251799813685254
                    }
            }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 25, 2021, 5:49pm UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/7 "2021-03-25T17:49:21Z")

</div>

Again, that is presentation. Have you tried the mutate+gsub?

---

<div class="post-metadata">

**Author:** ![Romanian\_Coder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/romanian_coder/32/84041_2.png) [@Romanian\_Coder](https://discuss.elastic.co/u/Romanian_Coder)\
**Post date:** [March 26, 2021, 3:10pm UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/8 "2021-03-26T15:10:51Z")

</div>

Nope, first, I need to write regexp to detect this value (because in this field may put valid json) so, if the actual value is "fire", I need to write something like this?

```auto
 if [value][value] =~ /^"\\"/ {
     mutate { 
          gsub => ["[value][value]", '"', "" ] 
     }
 }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 26, 2021, 4:14pm UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/9 "2021-03-26T16:14:24Z")

</div>

I would be very surprised if that worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2021, 4:14pm UTC](https://discuss.elastic.co/t/extract-value-from-regex-with-parentheses-in-if-condition/268190/10 "2021-04-23T16:14:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
